Cross-Site Scripting Vulnerability in Sourcecodester FAQ Bot with AI Assistant
CVE-2025-63639
6.1MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 November 2025
What is CVE-2025-63639?
The chat functionality in the Sourcecodester FAQ Bot with AI Assistant v1.0 is susceptible to Cross-Site Scripting (XSS) vulnerabilities. This security flaw arises from inadequate sanitization of user-supplied input, allowing attackers to inject harmful HTML or JavaScript scripts into chat messages. Once injected, these scripts can execute in the browsers of other users participating in the conversation, potentially compromising sensitive information and leading to further exploitation. Proper validation and encoding of user inputs are essential to mitigate this vulnerability.
